2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20036 | CRITICAL | 9.9 | 12.7% | Nov 15, 2024 | A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands w... |
| CVE-2023-20004 | MEDIUM | 4.4 | 0.2% | Nov 15, 2024 | Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to ove... |
| CVE-2023-20154 | HIGH | 8.1 | 0.9% | Nov 15, 2024 | A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote a... |
| CVE-2023-20125 | HIGH | 8.6 | 0.9% | Nov 15, 2024 | A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacke... |
| CVE-2023-4348 | — | — | — | Nov 15, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-4679 | MEDIUM | 5.5 | 0.3% | Nov 15, 2024 | A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del functi... |
| CVE-2023-2332 | MEDIUM | 4.8 | 0.4% | Nov 15, 2024 | A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versi... |
| CVE-2023-0737 | MEDIUM | 6.5 | 0.3% | Nov 15, 2024 | wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily d... |
| CVE-2023-0109 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability all... |
| CVE-2023-4458 | HIGH | 7.5 | 0.8% | Nov 14, 2024 | A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack o... |
| CVE-2023-4134 | MEDIUM | 5.5 | 0.2% | Nov 14, 2024 | A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device... |
| CVE-2023-34049 | MEDIUM | 6.7 | 0.2% | Nov 14, 2024 | The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force ... |
| CVE-2023-38920 | MEDIUM | 4.8 | 0.3% | Nov 13, 2024 | Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary co... |
| CVE-2023-35686 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This... |
| CVE-2023-35659 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the... |
| CVE-2023-52268 | CRITICAL | 9.1 | 0.6% | Nov 12, 2024 | The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user... |
| CVE-2023-50176 | HIGH | 8.8 | 0.6% | Nov 12, 2024 | A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allo... |
| CVE-2023-47543 | HIGH | 8.1 | 0.4% | Nov 12, 2024 | An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 throug... |
| CVE-2023-44255 | MEDIUM | 4.1 | 0.5% | Nov 12, 2024 | An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnal... |
| CVE-2023-32736 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMAT... |
| CVE-2023-40457 | — | — | 0.2% | Nov 11, 2024 | The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected... |
| CVE-2023-27195 | CRITICAL | 9.8 | 1.0% | Nov 8, 2024 | Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve th... |
| CVE-2023-1973 | HIGH | 7.5 | 1.3% | Nov 7, 2024 | A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of ... |
| CVE-2023-1932 | MEDIUM | 6.1 | 0.5% | Nov 7, 2024 | A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.... |
| CVE-2023-29126 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force pro... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now